SecurityFocus Newsletter #353
Conrad Schilbe <[email protected]> Thu, 08 Jun 2006 14:50:20 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #353
----------------------------------------
This Issue is Sponsored by: Watchfire
Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? See for yourself. Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000007ka5
------------------------------------------------------------------
I. FRONT AND CENTER
1. Browsers, phishing, and user interface design
2. Standards in desktop firewall policies
II. BUGTRAQ SUMMARY
1. LibTIFF tiff2pdf Remote Buffer Overflow Vulnerability
2. HP OpenView Storage Data Protector Remote Arbitrary Command Execution Vulnerability
3. Wikiwig WK_lang.PHP Remote File Include Vulnerability
4. Alex NewsEngine Newscomments.PHP SQL Injection Vulnerability
5. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
6. SuSE XScreenSaver Package Multiple Vulnerabilities
7. XScreenSaver Local Password Disclosure Vulnerability
8. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
9. DokuWiki Remote PHP Script Code Injection Vulnerability
10. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
11. Veritas Backup Exec Multiple Remote Denial of Service Vulnerabilities
12. DreamCost HostAdmin Multiple Remote File Include Vulnerabilities
13. Bookmark4U Multiple Remote File Include Vulnerabilities
14. ESTsoft InternetDisk Arbitrary File Upload and Script Execution Vulnerability
15. Kmita FAQ Multiple Input Validation Vulnerabilities
16. OSADS Alliance Database Board Comment HTML Injection Vulnerability
17. Microsoft Internet Explorer Frameset Denial of Service Vulnerability
18. Pixelpost Multiple SQL Injection Vulnerabilities
19. dotProject Unspecified Cross-Site Scripting Vulnerability
20. CyBoards PHP Lite Common.PHP Remote File Include Vulnerability
21. Quake 3 Engine CL_ParseDownload Remote Buffer Overflow Vulnerability
22. Particle Wiki Index.PHP SQL Injection Vulnerability
23. Particle Gallery Viewimage.PHP SQL Injection Vulnerability
24. ActiveState ActivePerl Local Privilege Escalation Vulnerability
25. Sun StorADE Local Privilege Escalation Vulnerability
26. CoolForum Editpost.PHP SQL Injection Vulnerability
27. Xine Filename Handling Remote Format String Vulnerability
28. Zlib Compression Library Buffer Overflow Vulnerability
29. Microsoft June Advance Notification Multiple Vulnerabilities
30. OpenSSH GSSAPI Credential Disclosure Vulnerability
31. FreeType TTF File Remote Denial of Service Vulnerability
32. Teca Scripts Guestex Multiple Input Validation Vulnerabilities
33. FreeType TTF File Remote Buffer Overflow Vulnerability
34. TikiWiki Multiple Cross-Site Scripting Vulnerabilities
35. Awstats Configuration File Remote Arbitrary Command Execution Vulnerability
36. Multiple Browser Marquee Denial of Service Vulnerability
37. MySQL Mysql_real_escape Function SQL Injection Vulnerability
38. KnowledgeTree Open Source Cross-site Scripting Vulnerability
39. ScriptsEZ Easy Ad-Manager Details.PHP Cross-Site Scripting Vulnerability
40. ScriptsEZ Chemical Dictionary Dictionary.PHP Cross-Site Scripting Vulnerability
41. ScriptsEZ E-Dating System Multiple Input Validation Vulnerabilities
42. GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability
43. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
44. OpenSSH SCP Shell Command Execution Vulnerability
45. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
46. Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
47. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
48. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
49. Tor Multiple Buffer Overflow/Information Disclosure/Denial of Service Vulnerabilities
50. DGbook HTML Injection Vulnerabilities
51. Awstats Remote Arbitrary Command Execution Vulnerability
52. AWStats AWstats.PL Cross-Site Scripting Vulnerability
53. Dia Filename Remote Format String Vulnerability
54. Dia Multiple Unspecified Remote Format String Vulnerabilities
55. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
56. CMS Mundo HTML Injection Vulnerability
57. Ingate Firewall and SIParator Remote SSL/TLS Handshake Denial Of Service Vulnerability
58. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
59. Zoo Misc.c Buffer Overflow Vulnerability
60. PostNuke Multiple Input Validation Vulnerabilities
61. Ingate Administrative Interface Cross-Site Scripting Vulnerability
62. Vice Stats VS_Resource.PHP SQL Injection Vulnerability
63. Calendar Express Month.PHP SQL Injection Vulnerability
64. MiraksGalerie Multiple Remote File Include Vulnerabilities
65. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
66. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
67. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
68. Linux Kernel Lease_Init Local Denial of Service Vulnerability
69. WebCalendar Index.PHP Information Disclosure Vulnerability
70. Qbik WinGate Remote HTTP Request Buffer Overflow Vulnerability
71. Shadow-Utils UserAdd Local Insecure Permissions Vulnerability
72. Alt-N MDaemon Remote Pre-Authentication IMAP Buffer Overflow Vulnerability
73. Microsoft NetMeeting Remote Memory Corruption Denial of Service Vulnerability
74. FreeRADIUS Multiple Remote Vulnerabilities
75. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
76. Fenice Remote Buffer Overflow and Denial Of Service Vulnerabilities
77. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
78. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
79. X.Org XRender Extension Buffer Overflow Vulnerability
80. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
81. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
82. Opera Web Browser Stylesheet Attribute Buffer Overflow Vulnerability
83. AZ Photo Album Script Pro Cross-Site Scripting Vulnerability
84. Multiple Vendor Web Browser JavaScript Key Filtering Vulnerability
85. LoudHush IAXclient Unspecified Security Vulnerability
86. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
87. TIBCO Rendezvous HTTP Interface Remote Buffer Overflow Vulnerability
88. TinyPHPForum Profile.PHP Local File Include Vulnerability
89. TIBCO Hawk Configuration Interface Local Buffer Overflow Vulnerability
90. D-Link DWL-2100AP Information Disclosure Vulnerability
91. MyBulletinBoard Private.PHP Cross-Site Scripting Vulnerability
92. Basic Analysis and Security Engine Multiple Remote File Include Vulnerabilities
93. Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
94. PyBlosxom Contributed Packages Comments Plugin Multiple Cross-Site Scripting Vulnerabilities
95. GANTTy Index.PHP Cross-Site Scripting Vulnerability
96. GD Graphics Library Remote Denial of Service Vulnerability
97. DreamAccount Multiple Remote File Include Vulnerabilities
98. Asterisk IAX2 Remote Denial of Service Vulnerability
99. Alex DownloadEngine Comments.PHP SQL Injection Vulnerability
100. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
III. SECURITYFOCUS NEWS
1. Researchers eye machines to analyze malware
2. Cybersecurity contests go national
3. Veterans Affairs warns of massive privacy breach
4. Blue Security folds under spammer's wrath
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Sr. Security Engineer, Sterling/Dulles
2. [SJ-JOB] Sr. Security Engineer, Sterling
3. [SJ-JOB] Management, Sterling/Dulles
4. [SJ-JOB] Security Engineer, Sterling
5. [SJ-JOB] Management, Dulles/Sterling
6. [SJ-JOB] Technology Risk Consultant, London, UK
7. [SJ-JOB] Quality Assurance, Columbia
8. [SJ-JOB] Instructor, Any
9. [SJ-JOB] Sales Representative, Vienna
10. [SJ-JOB] Sales Representative, New York
11. [SJ-JOB] Quality Assurance, Columbia
12. [SJ-JOB] Sales Engineer, Korea
13. [SJ-JOB] Sales Representative, Alexandria
14. [SJ-JOB] Sales Engineer, Ashburn
15. [SJ-JOB] Sales Engineer, Herndon
16. [SJ-JOB] Jr. Security Analyst, Redwood City
17. [SJ-JOB] Security Engineer, Netanya
18. [SJ-JOB] Database Security Architect, Lexington Park
19. [SJ-JOB] Application Security Architect, Lexington Park
20. [SJ-JOB] Penetration Engineer, Amsterdam
21. [SJ-JOB] Sales Engineer, Los Angeles
22. [SJ-JOB] Sr. Security Engineer, Frederick
23. [SJ-JOB] Developer, Iselin
24. [SJ-JOB] Security Consultant, Amsterdam
25. [SJ-JOB] Penetration Engineer, Atlanta
26. [SJ-JOB] Account Manager, Amsterdam
V. INCIDENTS LIST SUMMARY
1. Website Defacement
2. Moderator note: Compromised Windows Server thread
3. Strange mail with number in subject line and body
4. Compromised Windows Server
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Exploiting stack-overflows in Unicode/XPSP2 - Further questions
2. Exploiting in Unicode and XP SP2
VII. MICROSOFT FOCUS LIST SUMMARY
1. Blackhat Vegas 2006 ISA Training Announcement
2. Windows XP Services Best Practice
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Application level proxy for POP3/SMTP protocol
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Browsers, phishing, and user interface design
By Scott Granneman
Phishing works for so many reasons, we need to rethink browser and user interface design to provide some real-life security to the average user who doesn't see or understand the security cues.
http://www.securityfocus.com/columnists/405
2. Standards in desktop firewall policies
By Phil Kostenbader and Bob Donnelly
The idea of a common desktop firewall policy in any size organization is a very good thing. It makes responses to external or internal situations such as virus outbreaks or network-oriented propagation of viruses more predictable. In addition to providing a level of protection against port scanning, attacks or software vulnerabilities, it can provide the organizations local security team a baseline or starting point in dealing with such events.
http://www.securityfocus.com/infocus/1867
II. BUGTRAQ SUMMARY
--------------------
1. LibTIFF tiff2pdf Remote Buffer Overflow Vulnerability
BugTraq ID: 18331
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18331
Summary:
The tiff2pdf utility is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper boundary checks before copying user-supplied data into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying service to legitimate users.
2. HP OpenView Storage Data Protector Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 18095
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18095
Summary:
HP OpenView Storage Data Protector is prone to an arbitrary command-execution vulnerability.
Attackers can exploit this vulnerability to execute arbitrary commands in the context of the affected process. This may aid attackers in the compromise of the underlying system; other attacks are also possible.
3. Wikiwig WK_lang.PHP Remote File Include Vulnerability
BugTraq ID: 18291
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18291
Summary:
Wikiwig is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Wikiwig versions 4.1 and prior are vulnerable; other versions may also be affected.
4. Alex NewsEngine Newscomments.PHP SQL Injection Vulnerability
BugTraq ID: 18274
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18274
Summary:
NewsEngine is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
5. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
BugTraq ID: 17203
Remote: No
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/17203
Summary:
The Linux kernel is affected by local memory-disclosure vulnerabilities. These issues are due to the kernel's failure to properly clear previously used kernel memory before returning it to local users.
These issues allow an attacker to read kernel memory and potentially gather information to use in further attacks.
6. SuSE XScreenSaver Package Multiple Vulnerabilities
BugTraq ID: 9125
Remote: No
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/9125
Summary:
SuSE have reported that 'xscreensaver' packages shipped with SuSE Linux 9.0 are prone to multiple vulnerabilities. These issues include a crash when xscreensaver is handling the verification of authentication credentials. SuSE has also reported that xscreensaver is prone to several insecure temporary-file-creation vulnerabilities.
7. XScreenSaver Local Password Disclosure Vulnerability
BugTraq ID: 17471
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/17471
Summary:
XScreenSaver is prone to a local password-disclosure vulnerability. This issue is due to a flaw in the application that may result in the screen-unlock password being passed onto other applications that are already running on the computer.
This may disclose the password used to unlock the applications. The login password is typically used to unlock XScreenSaver, so this issue may reveal login passwords to attackers.
This issue is currently known to affect users who are running RDesktop on the locked computer, due to the interaction between the applications. This may result in the disclosure of the login password across the network. Other unknown applications in conjunction with XScreenSaver may result in a similar issue.
Version 4.14, and 4.16 are vulnerable to this issue; other versions may also be affected.
8. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
BugTraq ID: 18057
Remote: No
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18057
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability.
This issue arises because the software fails to handle exceptional conditions in a proper manner.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.
9. DokuWiki Remote PHP Script Code Injection Vulnerability
BugTraq ID: 18289
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18289
Summary:
DokuWiki is prone to a remote PHP code-injection vulnerability.
An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.
DokuWiki versions 2006-06-04 and prior are vulnerable; other versions may also be affected.
10. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
BugTraq ID: 15179
Remote: No
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/15179
Summary:
Fetchmail is susceptible to an information-disclosure vulnerability. This issue is due to a race condition in the 'fetchmailconf' configuration utility.
This issue allows local attackers to gain access to potentially sensitive information, including email authentication credentials, aiding them in further attacks.
Versions of Fetchmail prior to 6.2.9-rc6 include a vulnerable version of 'fetchmailconf'. Versions of 'fetchmailconf' prior to 1.43.2 and 1.49 are vulnerable.
11. Veritas Backup Exec Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 17098
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/17098
Summary:
Veritas Backup Exec is prone to multiple remote denial-of-service vulnerabilities.
These issues result in memory violations and memory exhaustion and lead to denial-of-service conditions in the affected applications. A restart is required to regain normal functionality in most cases.
Various versions of Backup Exec for Windows, Linux, and NetWare are vulnerable. NetBackup for NetWare Media Server Option releases, and Backup Exec Continuous Protection Server are also affected.
12. DreamCost HostAdmin Multiple Remote File Include Vulnerabilities
BugTraq ID: 18284
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18284
Summary:
HostAdmin is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
13. Bookmark4U Multiple Remote File Include Vulnerabilities
BugTraq ID: 18281
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18281
Summary:
Bookmark4U is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
14. ESTsoft InternetDisk Arbitrary File Upload and Script Execution Vulnerability
BugTraq ID: 18279
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18279
Summary:
ESTsoft InternetDisk is prone to an arbitrary file-upload and script-execution vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
This issue affects versions of InternetDisk downloaded prior to 19 April, 2006.
15. Kmita FAQ Multiple Input Validation Vulnerabilities
BugTraq ID: 18282
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18282
Summary:
Kmita FAQ is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
16. OSADS Alliance Database Board Comment HTML Injection Vulnerability
BugTraq ID: 18280
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18280
Summary:
OSADS Alliance Database is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
17. Microsoft Internet Explorer Frameset Denial of Service Vulnerability
BugTraq ID: 18277
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18277
Summary:
Microsoft Internet Explorer is affected by a denial-of-service vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner.
An attacker may exploit this issue by enticing a user to visit a malicious site and then to click anywhere on the page. This results in a denial-of-service condition in the application.
Internet Explorer version 6 is vulnerable to this issue; earlier versions may also be affected.
18. Pixelpost Multiple SQL Injection Vulnerabilities
BugTraq ID: 18276
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18276
Summary:
Pixelpost is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
19. dotProject Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 18275
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18275
Summary:
dotProject is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
20. CyBoards PHP Lite Common.PHP Remote File Include Vulnerability
BugTraq ID: 18272
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18272
Summary:
CyBoards PHP Lite is prone to a remote file-include vulnerability.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
21. Quake 3 Engine CL_ParseDownload Remote Buffer Overflow Vulnerability
BugTraq ID: 18271
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18271
Summary:
The Quake 3 engine is susceptible to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Remote attackers may exploit this issue to execute arbitrary machine code in the context of affected game clients. Failed exploit attempts will likely crash affected clients.
Quake 3 version 1.32c and Icculus.org Quake 3 revision 795 are vulnerable to this issue; other versions may also be affected. The affected game engine has been used to create many derivative games, which may also be affected.
22. Particle Wiki Index.PHP SQL Injection Vulnerability
BugTraq ID: 18273
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18273
Summary:
Particle Wiki is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
23. Particle Gallery Viewimage.PHP SQL Injection Vulnerability
BugTraq ID: 18270
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18270
Summary:
Particle Gallery is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
24. ActiveState ActivePerl Local Privilege Escalation Vulnerability
BugTraq ID: 18269
Remote: No
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18269
Summary:
ActiveState ActivePerl is susceptible to a local privilege-escalation vulnerability. This issue is due to a the software's failure to ensure that sufficiently secure directory permissions are enforced.
This issue allows local attackers to execute Perl script code with the privileges of other users executing ActivePerl on affected computers.
Version 5.8.8.817 of ActivePerl for Windows is vulnerable to this issue; other versions may also be affected.
25. Sun StorADE Local Privilege Escalation Vulnerability
BugTraq ID: 18266
Remote: No
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18266
Summary:
StorAde is prone to a privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges. This may facilitate a complete compromise of the affected computer.
26. CoolForum Editpost.PHP SQL Injection Vulnerability
BugTraq ID: 18268
Remote: Yes
Last Updated: 2006-06-05
Relevant URL: http://www.securityfocus.com/bid/18268
Summary:
CoolForum is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
27. Xine Filename Handling Remote Format String Vulnerability
BugTraq ID: 17769
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/17769
Summary:
The xine package is susceptible to a remote format-string vulnerability.
This issue arises when the application handles specially crafted filenames. An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then coercing unsuspecting users to try to execute the affected application with the malicious filename as an argument.
A successful attack may crash the application or lead to arbitrary code execution.
Version 0.99.4 of xine is vulnerable to this issue; other versions may also be affected.
28. Zlib Compression Library Buffer Overflow Vulnerability
BugTraq ID: 14162
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/14162
Summary:
Zlib is susceptible to a buffer-overflow vulnerability. This issue is due to the application's failure to properly validate input data before using it in a memory copy operation.
In certain circumstances, malformed input data during decompression may result in a memory buffer being overflowed. This may result in denial-of-service conditions or may allow remote code to execute in the context of applications that use the affected library.
29. Microsoft June Advance Notification Multiple Vulnerabilities
BugTraq ID: 18330
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18330
Summary:
Microsoft has released advance notification that they will be releasing twelve security bulletins for Windows on June 13, 2006. The highest severity rating for these issues is 'Critical'.
Further details about these issues are not currently available. Individual BIDs will be created and this record will be removed when the security bulletins are released.
30. OpenSSH GSSAPI Credential Disclosure Vulnerability
BugTraq ID: 14729
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/14729
Summary:
OpenSSH is susceptible to a GSSAPI credential-delegation vulnerability.
Specifically, if a user has GSSAPI authentication configured, and 'GSSAPIDelegateCredentials' is enabled, their Kerberos credentials will be forwarded to remote hosts. This occurs even when the user employs authentication methods other than GSSAPI to connect, which is not usually expected.
This vulnerability allows remote attackers to improperly gain access to GSSAPI credentials, allowing them to use those credentials to access resources granted to the original principal.
This issue affects versions of OpenSSH prior to 4.2.
31. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.
This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
32. Teca Scripts Guestex Multiple Input Validation Vulnerabilities
BugTraq ID: 16711
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/16711
Summary:
Guestex is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute all of the following in the context of the webserver process:
- arbitrary shell commands
- attacker-supplied HTML
- attacker-supplied script code
This may enable an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, or facilitate a compromise of the application and the underlying computer; other attacks are also possible.
33. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
34. TikiWiki Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18143
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18143
Summary:
TikiWiki is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
35. Awstats Configuration File Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 18327
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18327
Summary:
Awstats is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible.
36. Multiple Browser Marquee Denial of Service Vulnerability
BugTraq ID: 18165
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18165
Summary:
Multiple browsers are prone to a denial-of-service vulnerability when parsing certain HTML content.
Successfully exploiting this issue allows attackers to consume excessive CPU resources in affected browsers, denying service to legitimate users.
Mozilla Firefox version 1.5.0.3 is vulnerable to this issue; other versions and products may also be affected.
Internet Explorer 6.0 on Microsoft Windows XP is reported vulnerable to this issue; other versions may also be affected.
37. MySQL Mysql_real_escape Function SQL Injection Vulnerability
BugTraq ID: 18219
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18219
Summary:
MySQL is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise an application using a vulnerable database or to compromise the database itself.
MySQL versions prior to 5.0.22-1-0.1 and prior to 4.1.20 are vulnerable. Other versions may also be affected.
38. KnowledgeTree Open Source Cross-site Scripting Vulnerability
BugTraq ID: 18324
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18324
Summary:
KnowledgeTree Open Source is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize input before displaying it to users of the application.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
39. ScriptsEZ Easy Ad-Manager Details.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18339
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18339
Summary:
Easy Ad-Manager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
40. ScriptsEZ Chemical Dictionary Dictionary.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18337
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18337
Summary:
Chemical Dictionary is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
41. ScriptsEZ E-Dating System Multiple Input Validation Vulnerabilities
BugTraq ID: 18336
Remote: Yes
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18336
Summary:
E-Dating System is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
42. GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability
BugTraq ID: 18332
Remote: No
Last Updated: 2006-06-08
Relevant URL: http://www.securityfocus.com/bid/18332
Summary:
GDM is susceptible to an authentication-bypass vulnerability when users attempt to access the 'Configure Login Manager' option.
This issue allows local attackers to execute the 'Configure Login Manager' option with superuser privileges without entering valid superuser credentials. This allows them to make unauthorized configuration changes. This allows them to gain administrative access to affected computers, facilitating the complete compromise of affected computers.
43. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
BugTraq ID: 15629
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/15629
Summary:
Perl is susceptible to a format-string vulnerability. This issue is due to the programming language's failure to properly handle format specifiers in formatted-printing functions.
An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access.
Developers should treat the formatted printing functions in Perl as equivalently vulnerable to exploitation as the C library versions, and should properly sanitize all data passed in the format-specifier argument.
All applications that use formatted-printing functions in an unsafe manner should be considered exploitable.
44. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is susceptible to an SCP shell command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.
45. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
46. Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
BugTraq ID: 17372
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17372
Summary:
Kaffiene is reportedly affected by a remote buffer-overflow vulnerability because the application fails to perform sufficient boundary checks on user-supplied strings before copying them into finite stack-based buffers.
An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.
47. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
BugTraq ID: 18092
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18092
Summary:
PostgreSQL is prone to SQL-injection vulnerabilities. These issues are due to a potential mismatch of multibyte character conversions between PostgreSQL servers and client applications.
A successful exploit could allow an attacker to execute arbitrary SQL statements on affected servers. This may allow the attacker to compromise the targeted computer, access or modify data, or exploit other latent vulnerabilities.
PostgreSQL versions prior to 7.3.15, 7.4.13, 8.0.8, and 8.1.4 are vulnerable to these issues.
48. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
49. Tor Multiple Buffer Overflow/Information Disclosure/Denial of Service Vulnerabilities
BugTraq ID: 18323
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18323
Summary:
Tor is affected by multiple vulnerabilities. These issues include an integer overflow, denial of service, information disclosure, and a possible log-bypass error.
An attacker can exploit these issues to access sensitive information, crash the affected application, and potentially gain remote access to the underlying computer.
50. DGbook HTML Injection Vulnerabilities
BugTraq ID: 18310
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18310
Summary:
DGbook is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input to the Name, Homepage, and Address fields.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
51. Awstats Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 17844
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17844
Summary:
Awstats is prone to an arbitrary command-execution vulnerabilit. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible.
52. AWStats AWstats.PL Cross-Site Scripting Vulnerability
BugTraq ID: 17621
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17621
Summary:
AWStats is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
AWStats version 6.5 (build 1.857) and prior are vulnerable to this issue.
53. Dia Filename Remote Format String Vulnerability
BugTraq ID: 18078
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18078
Summary:
Dia is prone to a remote format-string vulnerability.
This issue arises when the application handles specially crafted filenames. An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then coercing unsuspecting users to open the malicious file with the affected application.
A successful attack may crash the application or lead to arbitrary code execution.
This issue affects Dia versions 0.95 and earlier.
54. Dia Multiple Unspecified Remote Format String Vulnerabilities
BugTraq ID: 18166
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18166
Summary:
Dia is prone to multiple unspecified format-string vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input before including it in the format-specifier argument of formatted-printing functions.
A successful attack may crash the application or lead to arbitrary code execution.
Specific information regarding affected versions of Dia is not currently available; this BID will be updated as further information is disclosed.
55. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
BugTraq ID: 18290
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18290
Summary:
SpamAssassin is prone to an arbitrary-command-execution vulnerability. This issue is due to an error in the application when processing a specially formatted input message when certain switches are set.
An attacker can exploit this issue to execute arbitrary comannds on the vulnerable computer with the privileges of the affected application.
56. CMS Mundo HTML Injection Vulnerability
BugTraq ID: 18316
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18316
Summary:
CMS Mundo is prone to an HTML-injection vulnerability because it fails to properly sanitize HTML and script code from user-supplied input to the search form input box.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
57. Ingate Firewall and SIParator Remote SSL/TLS Handshake Denial Of Service Vulnerability
BugTraq ID: 18318
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18318
Summary:
Ingate Firewall and SIParator products are prone to a remote denial-of-service vulnerability.
This issue allows remote attackers to cause affected services to crash and restart, potentially denying service to legitimate users.
This vulnerability is exploitable only if SSL/TLS has been enabled in the SIP module or in the webserver.
Versions of Ingate Firewall and SIParator prior to 4.4.1 are vulnerable to this issue.
58. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
59. Zoo Misc.c Buffer Overflow Vulnerability
BugTraq ID: 16790
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/16790
Summary:
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.
60. PostNuke Multiple Input Validation Vulnerabilities
BugTraq ID: 18319
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18319
Summary:
PostNuke is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
61. Ingate Administrative Interface Cross-Site Scripting Vulnerability
BugTraq ID: 14812
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/14812
Summary:
Ingate Firewall and SIParator are prone to a cross-site scripting vulnerability. This is due to a failure to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting administrative user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
62. Vice Stats VS_Resource.PHP SQL Injection Vulnerability
BugTraq ID: 18317
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18317
Summary:
Vice Stats is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
63. Calendar Express Month.PHP SQL Injection Vulnerability
BugTraq ID: 18314
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18314
Summary:
Calendar Express is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
64. MiraksGalerie Multiple Remote File Include Vulnerabilities
BugTraq ID: 18313
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18313
Summary:
MiraksGalerie is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
65. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
66. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17955
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17955
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel deadlock and infinite recursion, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
67. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17910
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17910
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
Note that a valid SCTP endpoint must be listening.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
68. Linux Kernel Lease_Init Local Denial of Service Vulnerability
BugTraq ID: 17943
Remote: No
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17943
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'lease_init' function.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.16.
69. WebCalendar Index.PHP Information Disclosure Vulnerability
BugTraq ID: 18175
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18175
Summary:
WebCalendar is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve the contents of arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
WebCalendar version 1.0.3 is vulnerable; other versions may be affected.
70. Qbik WinGate Remote HTTP Request Buffer Overflow Vulnerability
BugTraq ID: 18312
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18312
Summary:
Qbik WinGate is susceptible to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of affected proxy servers. This facilitates the remote compromise of affected computers. Failed exploit attempts will crash the proxy server, denying service to legitimate users.
Version 6.1.1.1077 is vulnerable to this issue; other versions may also be affected.
71. Shadow-Utils UserAdd Local Insecure Permissions Vulnerability
BugTraq ID: 18111
Remote: No
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18111
Summary:
The useradd utility in shadow-utils is susceptible to a local insecure-permissions vulnerability. This issue is due to a race-condition between when user mailboxes are created and when permissions are set on the file.
A local, unprivileged attacker can exploit this issue to gain access to newly created mailbox files. This may allow them to directly inject forged email messages to aid them in social-engineering attacks. Attackers may also be able to inject data into the mailbox file that will cause mail applications to fail to access the file, denying email access to targeted users. Other attacks may also be possible.
Version 4.0.3 of shadow-utils is vulnerable to this issue; other versions may also be affected.
72. Alt-N MDaemon Remote Pre-Authentication IMAP Buffer Overflow Vulnerability
BugTraq ID: 18129
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18129
Summary:
Alt-N MDaemon IMAP Server is susceptible to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote, unauthenticated attackers to execute arbitrary machine code in the context of affected servers. This facilitates the complete compromise of affected computers.
Specific information regarding affected versions is not currently available. This BID will be updated as further information is disclosed.
UPDATE: The reporter of this issue states that this issue may not be exploitable. This BID may be retired in the future.
73. Microsoft NetMeeting Remote Memory Corruption Denial of Service Vulnerability
BugTraq ID: 18311
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18311
Summary:
Microsoft NetMeeting is prone to a remote memory-corruption vulnerability. This issue is due to the application's failure to properly handle malformed network traffic.
This issue allows remote attackers to crash affected applications or to consume excessive CPU resources. Due to the nature of this issue, attackers might be able to exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed.
Microsoft NetMeeting version 3.01 is vulnerable to this issue; other versions may also be affected.
74. FreeRADIUS Multiple Remote Vulnerabilities
BugTraq ID: 14775
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/14775
Summary:
FreeRADIUS is susceptible to multiple remote vulnerabilities:
- Memory-handling vulnerabilities. These issues may allow remote attackers to crash affected services or possibly execute arbitrary machine code in the context of the vulnerable application.
- File descriptor leak. Attackers may exploit this to gain access to files that they may not normally have access to.
- The LDAP module contains a flaw whereby attacker-specified data may be passed on to the configured LDAP database without proper input sanitization.
These issues are all reported to affect version 1.0.4 of FreeRADIUS; previous versions are also likely vulnerable to one or more of these issues.
**Update: The vendor has posted a response to these issues. Please see "Response to Suse Audit Report on FreeRADIUS" for further details.
75. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
BugTraq ID: 14759
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/14759
Summary:
Multiple products are prone to a buffer overflow when handling ACE archives that contain files with overly long names.
This may be exploited to execute arbitrary code in the context of the user who is running the application. The vulnerability is considered remotely exploitable in nature because malicious ACE archives will likely originate from an external, untrusted source.
76. Fenice Remote Buffer Overflow and Denial Of Service Vulnerabilities
BugTraq ID: 17678
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17678
Summary:
Fenice is susceptible to multiple remote vulnerabilities:
- A buffer-overflow vulnerability. The application fails to perform sufficient bounds checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue potentially allows remote attackers to execute arbitrary machine code in the context of the affected server process. Failed exploit attempts will likely crash the application, denying service to legitimate users.
- A denial-of-service vulnerability due to an integer-overflow flaw. This issue allows remote attackers to crash the affected application, denying service to legitimate users.
Version 1.10 of Fenice is vulnerable to these issues; other versions may also be affected.
77. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
BugTraq ID: 15523
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/15523
Summary:
IPsec-Tools is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to handle exceptional conditions when in 'AGGRESSIVE' mode.
An attacker can exploit this issue to crash the application, thus denying service to legitimate users.
These vulnerabilities were discovered by, and may be reproduced by, the University of Oulu Secure Programming Group PROTOS IPSec Test Suite.
78. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
BugTraq ID: 16756
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/16756
Summary:
SquirrelMail is susceptible to multiple cross-site scripting and IMAP-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.
An attacker may leverage any of the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
An attacker may leverage the IMAP-injection issue to execute arbitrary IMAP commands on the configured IMAP server. This may aid attackers in further attacks and allow them to exploit latent vulnerabilities in the IMAP server.
79. X.Org XRender Extension Buffer Overflow Vulnerability
BugTraq ID: 17795
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17795
Summary:
The X.Org X Window System is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code with elevated privileges. This may facilitate a compromise of the affected computer.
80. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Multiple Mozilla products are prone to a script-execution vulnerability.
The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client.
The following mozilla products are vulnerable to this issue:
- Mozilla Thunderbird, versions prior to 1.5.0.2, and prior to 1.0.8
- Mozilla SeaMonkey, versions prior to 1.0.1
- Mozilla Suite, versions prior to 1.7.13
81. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.
These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1
82. Opera Web Browser Stylesheet Attribute Buffer Overflow Vulnerability
BugTraq ID: 17513
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/17513
Summary:
Opera is prone to a buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before using it in a string-copy operation.
This issue allows remote attackers to crash affected web browsers. Due to the nature of this issue, attackers may be able to exploit this issue to execute machine code, but this has not been confirmed.
Opera version 8.52 is vulnerable to this issue; other versions may also be affected.
83. AZ Photo Album Script Pro Cross-Site Scripting Vulnerability
BugTraq ID: 18306
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18306
Summary:
AZ Photo Album Script Pro is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
84. Multiple Vendor Web Browser JavaScript Key Filtering Vulnerability
BugTraq ID: 18308
Remote: Yes
Last Updated: 2006-06-07
Relevant URL: http://www.securityfocus.com/bid/18308
Summary:
Multiple web browsers are prone to a JavaScript key-filtering vulnerability. This issue is due to the failure of the browsers to securely handle keystroke input from users.
This issue is demonstrated to allow attackers to divert keystrokes from one input form in a webpage to a hidden file-upload dialog in the same page. This may allow remote attackers to initiate file uploads from unsuspecting users. Other attacks may also be possible.
Exploiting this issue requires that users manually type the full path of files that attackers wish to download. This may require substantial typing from targeted users, so attackers will likely use keyboard-based games, blogs, or other similar pages to entice users to enter the required keyboard input to exploit this issue.
Reportedly, Mozilla Suite, Mozilla Firefox, Mozilla SeaMonkey, Netscape Navigator, and Microsoft Internet Explorer are all vulnerable to this issue.
85. LoudHush IAXclient Unspecified Security Vulnerability
BugTraq ID: 18307
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18307
Summary:
LoudHush is prone to an unspecified security vulnerability. This issue affects the 'iaxclient' library.
This issue affects version 1.3.6; other versions may also be affected. This issue is likely related to BID 18295.
86. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
BugTraq ID: 17171
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/17171
Summary:
FreeRADIUS is prone to an authentication-bypass vulnerability. The issue exists in the EAP-MSCHAPv2 state machine. Bypassing authentication could also cause the server to crash.
FreeRADIUS versions from 1.0.0 to 1.1.0 are vulnerable.
87. TIBCO Rendezvous HTTP Interface Remote Buffer Overflow Vulnerability
BugTraq ID: 18301
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18301
Summary:
TIBCO Rendezvous is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly check boundaries of user-supplied command-line argument data before copying it to an insufficiently sized memory buffer.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers. The affected component may be installed as a service with administrative privileges on Microsoft Windows computers.
TIBCO Hawk versions prior to 4.6.1, TIBCO Runtime Agent versions prior to 5.4, and TIBCO Rendezvous versions prior to 7.5.1 are vulnerable to this issue.
88. TinyPHPForum Profile.PHP Local File Include Vulnerability
BugTraq ID: 18304
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18304
Summary:
TinyPHPForum is prone to a local file-include vulnerability. This is due to improper sanitization of user-supplied input.
A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.
Version 3.6 of TinyPHPForum is vulnerable to this issue; other versions may also be affected.
89. TIBCO Hawk Configuration Interface Local Buffer Overflow Vulnerability
BugTraq ID: 18300
Remote: No
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18300
Summary:
TIBCO Hawk is susceptible to a local buffer-overflow vulnerability. This issue is due to the application's failure to properly check boundaries of user-supplied command-line argument data before copying it to an insufficiently sized memory buffer.
Attackers may exploit this issue to execute arbitrary machine code with elevated privileges. This is a vulnerability only if the affected software is installed with setuid-privileges on UNIX computers or if it is installed as a service running with administrative privileges on Microsoft Windows computers.
TIBCO Hawk versions prior to 4.6.1 and TIBCO Runtime Agent versions prior to 5.4 are vulnerable to this issue.
90. D-Link DWL-2100AP Information Disclosure Vulnerability
BugTraq ID: 18299
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18299
Summary:
D-Link DWL-2100AP devices are susceptible to a remote information-disclosure vulnerability. The devices fail to properly secure configuration information.
This issue allows remote, unauthenticated attackers to gain access to potentially sensitive configuration information from affected devices. This may aid them in further attacks.
91. MyBulletinBoard Private.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18297
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18297
Summary:
MyBulletinBoard is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
92. Basic Analysis and Security Engine Multiple Remote File Include Vulnerabilities
BugTraq ID: 18298
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18298
Summary:
Basic Analysis and Security Engine is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
93. Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17536
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/17536
Summary:
Tiny Web Gallery is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.4 and prior are vulnerable.
94. PyBlosxom Contributed Packages Comments Plugin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18292
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18292
Summary:
PyBlosxom Contributed Packages is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Contributed Packages for Pyblosxom version 1.2.2 is vulnerable; other versions may also be affected.
95. GANTTy Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18296
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18296
Summary:
GANTTy is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
96. GD Graphics Library Remote Denial of Service Vulnerability
BugTraq ID: 18294
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18294
Summary:
The GD Graphics Library is prone to a denial-of-service vulnerability. Attackers can trigger an infinite-loop condition when the library tries to handle malformed image files.
This issue allows attackers to consume excessive CPU resources on computers that use the affected software. This may deny service to legitimate users.
GD version 2.0.33 is vulnerable to this issue; other versions may also be affected.
97. DreamAccount Multiple Remote File Include Vulnerabilities
BugTraq ID: 18278
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18278
Summary:
DreamAccount is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
DreamAccount versions 3.1 and prior are vulnerable; other versions may also be affected.
98. Asterisk IAX2 Remote Denial of Service Vulnerability
BugTraq ID: 18295
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18295
Summary:
Asterisk is prone to a remote denial-of-service vulnerability. This issue is most likely due to a design error within the application.
This vulnerability allows remote attackers to crash the server, denying further service to legitimate users.
99. Alex DownloadEngine Comments.PHP SQL Injection Vulnerability
BugTraq ID: 18293
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/18293
Summary:
DownloadEngine is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
100. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-06-06
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Researchers eye machines to analyze malware
By: Robert Lemos
Automated classification of malicious software could make recognition of threats faster and names more consistent, but researchers cannot agree on what such a system should look like.
http://www.securityfocus.com/news/11395
2. Cybersecurity contests go national
By: Robert Lemos
America's heartland has become an incubator for competitions pitting high-school and college students against teams of hackers in defense of a corporate network.
http://www.securityfocus.com/news/11394
3. Veterans Affairs warns of massive privacy breach
By: Robert Lemos
The records of nearly 26.5 million veterans--including names, social security numbers and dates of birth--were stolen from the home of a federal employee.
http://www.securityfocus.com/news/11393
4. Blue Security folds under spammer's wrath
By: Robert Lemos
Under threat of further attacks on its service and users, an Israeli anti-spam startup decides to shutter its service.
http://www.securityfocus.com/news/11392
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sr. Security Engineer, Sterling/Dulles
http://www.securityfocus.com/archive/77/436317
2. [SJ-JOB] Sr. Security Engineer, Sterling
http://www.securityfocus.com/archive/77/436331
3. [SJ-JOB] Management, Sterling/Dulles
http://www.securityfocus.com/archive/77/436337
4. [SJ-JOB] Security Engineer, Sterling
http://www.securityfocus.com/archive/77/436314
5. [SJ-JOB] Management, Dulles/Sterling
http://www.securityfocus.com/archive/77/436316
6. [SJ-JOB] Technology Risk Consultant, London, UK
http://www.securityfocus.com/archive/77/436299
7. [SJ-JOB] Quality Assurance, Columbia
http://www.securityfocus.com/archive/77/436305
8. [SJ-JOB] Instructor, Any
http://www.securityfocus.com/archive/77/436308
9. [SJ-JOB] Sales Representative, Vienna
http://www.securityfocus.com/archive/77/436310
10. [SJ-JOB] Sales Representative, New York
http://www.securityfocus.com/archive/77/436311
11. [SJ-JOB] Quality Assurance, Columbia
http://www.securityfocus.com/archive/77/436312
12. [SJ-JOB] Sales Engineer, Korea
http://www.securityfocus.com/archive/77/436298
13. [SJ-JOB] Sales Representative, Alexandria
http://www.securityfocus.com/archive/77/436307
14. [SJ-JOB] Sales Engineer, Ashburn
http://www.securityfocus.com/archive/77/436318
15. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/436342
16. [SJ-JOB] Jr. Security Analyst, Redwood City
http://www.securityfocus.com/archive/77/436142
17. [SJ-JOB] Security Engineer, Netanya
http://www.securityfocus.com/archive/77/436139
18. [SJ-JOB] Database Security Architect, Lexington Park
http://www.securityfocus.com/archive/77/436140
19. [SJ-JOB] Application Security Architect, Lexington Park
http://www.securityfocus.com/archive/77/436141
20. [SJ-JOB] Penetration Engineer, Amsterdam
http://www.securityfocus.com/archive/77/436136
21. [SJ-JOB] Sales Engineer, Los Angeles
http://www.securityfocus.com/archive/77/436137
22. [SJ-JOB] Sr. Security Engineer, Frederick
http://www.securityfocus.com/archive/77/436138
23. [SJ-JOB] Developer, Iselin
http://www.securityfocus.com/archive/77/435707
24. [SJ-JOB] Security Consultant, Amsterdam
http://www.securityfocus.com/archive/77/435708
25. [SJ-JOB] Penetration Engineer, Atlanta
http://www.securityfocus.com/archive/77/435710
26. [SJ-JOB] Account Manager, Amsterdam
http://www.securityfocus.com/archive/77/435711
V. INCIDENTS LIST SUMMARY
---------------------------
1. Website Defacement
http://www.securityfocus.com/archive/75/436335
2. Moderator note: Compromised Windows Server thread
http://www.securityfocus.com/archive/75/436175
3. Strange mail with number in subject line and body
http://www.securityfocus.com/archive/75/436185
4. Compromised Windows Server
http://www.securityfocus.com/archive/75/436040
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Exploiting stack-overflows in Unicode/XPSP2 - Further questions
http://www.securityfocus.com/archive/82/436340
2. Exploiting in Unicode and XP SP2
http://www.securityfocus.com/archive/82/436149
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Blackhat Vegas 2006 ISA Training Announcement
http://www.securityfocus.com/archive/88/436042
2. Windows XP Services Best Practice
http://www.securityfocus.com/archive/88/435926
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Application level proxy for POP3/SMTP protocol
http://www.securityfocus.com/archive/91/435551
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire
Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? See for yourself. Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000007ka5